use-sapiom

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The improved assessment confirms that the manifest is coherent with a centralized cloud-tool aggregator (Sapiom MCP) and does not exhibit explicit malicious indicators in isolation. The principal risk stems from its broad, high-privilege surface and external dependency on vendor infrastructure. Therefore, enforce strict access control, project-scoped API keys, encryption at rest/in transit, transparent data governance, and comprehensive audit trails before enabling automation across sandboxes, databases, queues, and governance features.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 3, 2026, 10:26 PM
Package URL
pkg:socket/skills-sh/sapiom%2Fskills%2Fuse-sapiom%2F@16a64c38f38f9d12fd07e79dcc4d9a0325c6c2cf